Improper input validation in Oracle Java SE - CVE-2020-2585

 

Improper input validation in Oracle Java SE - CVE-2020-2585

Published: February 10, 2020


Vulnerability identifier: #VU25089
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-2585
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The vulnerability exists due to improper input validation within the JavaFX component in Java SE. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.


Affected software

Oracle Java SE
Gentoo Linux
EMC ECS
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Data Protection Search

How to mitigate CVE-2020-2585

Install updates from vendor's website.

EMC ECS - update to 3.5.0.1
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Data Protection Search - update to 19.3.0

External References

Related Security Bulletins